this post was submitted on 30 Sep 2023
157 points (74.0% liked)

Programming

17374 readers
253 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 1 year ago
MODERATORS
 

This thread is frustrating. Everyone seems more interested in nitpicking the specifics of what OP is saying and are ignoring that a forum sends you your password (not an automatically generated one) in an email on registration.

you are viewing a single comment's thread
view the rest of the comments
[–] mosiacmango@lemm.ee 126 points 1 year ago* (last edited 1 year ago) (3 children)

Larian stated on their forum they fixed this behavior and shifted to https 3 years ago. When this was linked several times in thread, people asked OP when this screenshot occured, and OP ignored the questions. Pretty clear that this is a very old screenshot of what is now a non issue.

What's to discuss besides OP trying to stir up drama about issues that were resolved years ago?

[–] Pyroglyph@lemmy.world 28 points 1 year ago (1 children)

this is a very old screenshot

What do you mean? It says "0 minutes ago"! Clearly it's very recent! /s

[–] BigDanishGuy@sh.itjust.works 2 points 1 year ago

Yeah this is the internet, not lame stream media that lies to you. /r

[–] ono@lemmy.ca 15 points 1 year ago* (last edited 1 year ago) (1 children)

FWIW, it's not fixed. The screen shot may very well be recent.

(The post in question was still bad reporting, though, for the reasons I detailed in my other comment here.)

[–] elbarto777@lemmy.world 7 points 1 year ago* (last edited 1 year ago) (2 children)

Are you saying that the parent poster is giving incorrect information?

Edit: Oy, straight from their membership administration docs (emphasis mine):

Additionally, using the buttons below, you can delete the user, email the user's password to him/her, (etc)

[–] ono@lemmy.ca 7 points 1 year ago* (last edited 1 year ago)

Are you saying that the parent poster is giving incorrect information?

Yes. mosiacmango's comment repeated what others had already said (right down to specific words that I used in the original thread and here), and then jumped to this conclusion:

Pretty clear that this is a very old screenshot of what is now a non issue.

Everything about that statement is false. While the circumstances made it seem likely that the screenshot was old, it was not clearly so, and in fact, it turns out the issue is still present. I checked it. A registration email from the test I ran yesterday looked just like the screenshot in question, cleartext password and all.

Given that Larian reported the issue fixed three years ago, it's possible that they fixed it locally and some time later upgraded to a new version of the forum software, thereby overwriting the local fix. Perhaps mosiacmango should have considered that before posting incorrect speculation as if it were fact.

[–] ____@infosec.pub 4 points 1 year ago

Ouch... This should never be possible, in any world. If the password can be emailed, it can be seen. If it can be seen, it can be stolen.